Technical Advisory Board (TAB)

 View Only

Template for risk assessment

  • 1.  Template for risk assessment

    Posted 08-29-2012 20:32
    Hi Greg, The TAB assembled some thoughts on considerations for IT risk assessment in the event they are useful to you in your work to evaluate our current levels of risk for the Board. This is a high-level template for risk assessment that we hope will be helpful. Risk assessment Template: ========================= 1. Make a list of all User-driven "operations" (driven through OASIS portal / member site by members) 2. Make a list of all "internal" operations/processes (e.g. back-up, etc.) taking place on a regular basis. 3. Make a list of all persistent data that OASIS maintains (docs, mails, TCprocess status, member data...) and their medium, their management mode (DB? file? closed system like issue tracking?) 4. Make a list of all the major hardware and software systems. 1. Risk assessment for User-driven Operations: ------------------------------------------ - for each operation/process that a user (member/TCadmin) can drive from the OASIS portal, in case of a crash what are those that: o may/will leave the System in an inconsistent state ( a state that the system would never be in under normal operation processing) o may/will leave the operation partially done (neither undone nor complete), with unclear awareness of as to whether it was completed, undone or partially done complete/partial/undone? o may/will cancel the operation or whatever part of it has apparently been done successfully prior to the crash, with unclear awareness of what part of the operation is cancelled? - For all of the above, is there a clear understanding by the user as to what they must do once the system is up again, regarding the operations occurring at crash time e.g to retry, to wait until notified etc. 2. Risk assessment for Internal Operations (e.g. back-up / archival, synchronization, internal processes.): ---------------------------------------- - for each operation/process that is initiated by IT Staff, in case of a crash what are those that: o may/will leave the System in an inconsistent state ( a state that the system would never be in under normal operation processing) o may/will leave the operation partially done (neither undone nor complete), with unclear awareness of as to whether it was completed, undone or partially done complete/partial/undone? o may/will cancel the operation or whatever part of it has apparently been done successfully prior to the crash, with unclear awareness of what part of the operation is cancelled? - For all of the above, is there a clear understanding by IT staff as to what they must do once the system is up again, regarding the operations occurring at crash time e.g to retry, to wait until notified etc. - is there clear documentation of the processes and procedures that must take place to get the systems back into a consistent state? - is there clear documentation of the processes and procedures to inform user what operations have failed and what they need to do to recover. 3. Risk assessment for existing Persistent Data: -------------------------------------------- - for each type of persistent data: o may/will there be data consistency and/or integrity integrity issues affected by an unplanned shutdown? o if yes is there a process to recover data in a consistent state? How recent is the last consistent state? o is there a means/process to make administrator / staff aware of a data state alteration? Please let us know if you have any questions on the above. /chet ---------------- Chet Ensign Director of Standards Development and TC Administration OASIS: Advancing open standards for the information society http://www.oasis-open.org Primary: +1 973-996-2298 Mobile: +1 201-341-1393 TC Administration information and support is available at http://www.oasis-open.org/resources/tcadmin Follow OASIS on: LinkedIn: http://linkd.in/OASISopen Twitter: http://twitter.com/OASISopen Facebook: http://facebook.com/oasis.open